PT-2026-83371 · Unknown · Mapfish-Print

CVE-2026-55848

·

Published

2026-08-28

·

Updated

2026-08-29

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions mapfish-print versions prior to 3.28.30 mapfish-print versions prior to 3.30.32 mapfish-print versions prior to 3.31.24 mapfish-print versions prior to 3.33.16 mapfish-print versions prior to 4.0.5
Description MapFish Print fails to disable external entities and external DTDs when parsing XML from a GML layer URL. An unauthenticated attacker can provide a malicious URL to the /api/print3/print endpoint, which is then processed by the GmlLayer.java function. This allows the attacker to use XML External Entity (XXE) injection to read sensitive local files, such as operating-system account data, Kubernetes service-account tokens, and certificates. Additionally, by replacing the file entity target with an internal HTTP endpoint, an attacker can perform server-side request forgery (SSRF), which is a technique used to make the server send requests to internal resources it has access to.
Recommendations Update to version 3.28.30. Update to version 3.30.32. Update to version 3.31.24. Update to version 3.33.16. Update to version 4.0.5.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55848
GHSA-5V29-34H8-V68R

Affected Products

Mapfish-Print